The controlled disclosure of third parties authorised to process customer-controlled personal information for Bibeno, including purpose, information, people, locations, onward processing, safeguards, retention, and change rights.
Status: Effective 14 August 2026Version: 1.0.0Content hash: 75f988abae16b84eca3e812302b9b907d2c54404f7945d0d259bb07b5f3383eb
1. Status and publication boundary
A provider name detected in configuration, source code, an invoice, a development environment, or a marketing page is not sufficient evidence that the provider is enabled, contracted, located in a particular region, or approved to process production personal information.
2. What this list covers
A subprocessor or sub-operator is a third party engaged by Bibeno to process customer-controlled personal information in Bibeno's operator role. Providers acting only for Bibeno's own responsible-party purposes, independent payment parties, customer-selected providers, and disabled providers are identified separately where that distinction is material.
The Data Processing Agreement governs authorisation, contracting, monitoring, international processing, incidents, assistance, audit evidence, and exit. This list supplies the current provider-specific facts and must be read with that agreement and the Security Measures Schedule.
3. Information required for each approved provider
Exact legal entity and service name, provider role, contract owner, and service purpose.
Categories of personal information and data subjects processed, with optional features distinguished from core processing.
Primary storage, processing, backup, failover, telemetry, and support-access countries or regions.
Authorised onward subprocessors or a verified route to the current onward-provider list.
POPIA section 72 or other approved international-transfer safeguard and its controlled evidence identifier.
Security, privacy, incident, deletion, retention, business-continuity, audit, and customer-assistance commitments.
Contract or DPA, security review, retention evidence, exit plan, approval date, evidence expiry, and last review date.
Whether the provider is mandatory, optional, customer-controlled, restricted to a feature or territory, or disabled.
4. Provider categories requiring verification
Frontend and application hosting, networking, content delivery, domains, and DNS.
Backend compute, databases, object and file storage, backups, queues, and scheduled operations.
Subscription payment processing, invoicing support, fraud controls, and provider transaction records.
Transactional email, customer-configured email or SMS, support communications, and message-delivery evidence.
Error monitoring, security telemetry, product analytics, performance diagnostics, and alerting when enabled.
Support ticketing, attachment storage and malware scanning, privacy requests, and security-incident operations.
App distribution, device services, customer-selected integrations, and any future identity, automation, or AI provider.
The public list contains only categories that are actually enabled in the approved production architecture and identifies optional processing clearly. A configured category may not be omitted from the controlled register even if its provider is still unverified or disabled.
5. Customer-selected providers
A customer may connect its own email, SMS, payment, storage, identity, or other provider. The customer selects and contracts with that provider and is responsible for its lawful basis, notices, settings, regions, retention, recipients, and exit. The provider does not become Bibeno's subprocessor merely because Bibeno supports a connection.
Bibeno remains responsible for the supported integration boundary: authentication, minimum data exchange, tenant and branch scoping, secure transport, failure handling, logs, revocation, deletion, and preventing a customer-selected provider from receiving information outside the customer's instruction.
6. New and replacement providers
Bibeno gives reasonable advance notice of a new or replacement subprocessor where the change materially affects customer-controlled information. The notice identifies the provider, purpose, information, people, locations, transfer safeguard, expected date, and objection route.
A customer may make a reasoned data-protection objection during the stated period. Bibeno will assess the risk and a reasonable alternative such as configuration, regional option, provider replacement, optional-feature disablement, or termination of the affected service. An objection is not accepted merely to avoid an unrelated commercial obligation.
An urgent security replacement may occur on shorter notice where delay would materially increase risk. Bibeno records the reason, completes the same verification, and provides notice as soon as reasonably possible.
7. International processing and onward changes
An international location or remote support route is approved only with a valid POPIA section 72 safeguard and current evidence. A provider may not silently add a processing region, support location, or onward subprocessor outside the approved boundary.
Bibeno reviews material provider notices and updates this list and the controlled register before the change is relied on for production processing. Where an onward change alters risk materially, Bibeno applies the same customer notice and objection process.
8. History and contact
Each published list is immutable and has a version and resolved-content hash. The version history preserves added, removed, and materially changed providers and whether a customer notice or re-acceptance was required.
Provider, location, transfer, and objection questions may be sent to support@bibeno.co.za or through the authenticated support route. Bibeno may provide additional confidential assurance under suitable protections but does not disclose provider secrets, another customer's information, or privileged material.
Choose your cookie preferences
Essential storage is always active. Optional analytics and marketing tools remain off unless you allow them. Read more.